Anvilogic Forge Threat Research Reports
Here you can find an accumulation of trending threats published weekly by the Anvilogic team.
We curate threat intelligence to provide situational awareness and actionable insights
Atomic detections that serve as the foundation of our detection framework.
Risk, pattern, and sequence-based detections utilizing the outputs of Threat Identifiers as a means of identifying actual threats.
• Threat News Reports
• Trending Threat Reports
• ResearchArticles
Forge Report: First Half Threat Trends of 2024



Featured Threat Reports


All Threat Reports
Miratorg Agribusiness Holding - Ransomware Attack
On March 22, 2022, Miratorg Agribusiness Holding, a meat supplier based in Moscow, suffered a ransomware attack using Windows BitLocker. The attack, believed to be an act of sabotage rather than financially motivated, targeted VetIS, a state information system used by veterinary services and companies in the field. Miratorg suggests the attack may be linked to the Russia-Ukraine conflict, citing hostility from the West. The company is currently working to restore its business services.
MicroBackdoor Attacks Ukraine
On March 9, 2022, Ukraine's Computer Emergency Response Team (CERT-UA) warned that MicroBackdoor malware is targeting Ukrainian government agencies. The malware, distributed via phishing emails, contains a zip file with files that execute malicious VBScript code. CERT-UA's intelligence indicates that the malware was created in January 2022.
HermeticRansom Ransomware Decryptor Released by Avast
Avast has released a decryptor for HermeticRansom, a ransomware component of HermeticWiper. CrowdStrike found a weakness in its encryption schema, allowing files to be decrypted. The ransomware, written in Go, serves as a decoy for the wiper and encrypts files in various paths. The flaw indicates possible inexperience or limited effort by the malware author.
Hacked Sites Spreads Fake "Capitulation" News
On March 3rd, 2022, the Ukrainian State Service of Special Communication and Information Protection (SSSCIP) identified hacked government sites spreading fake news about Ukraine's surrender to Russia. The SSSCIP actively shares updates and warnings about these compromised sites on Twitter, emphasizing that the surrender claims are false.
Anonymous Attacks Russian Government Sites
On March 15th, 2022, the Anonymous group launched DDoS attacks taking down multiple Russian government sites, including FSB and the Stock Exchange. The attacks caused a seven-hour outage, with some sites remaining inaccessible.
DoubleZero Wiper
On March 22, 2022, Symantec reported on the DoubleZero wiper, written in .NET and designed to obfuscate code and zero out critical system files and registry keys. This latest addition joins other wipers like WhisperGate, HermeticWiper, IsaacWiper, and CaddyWiper.
Intelligence Levels for Threat Reports
Tactical
Detectable threat behaviors for response with threat scenarios or threat identifiers.
Strategic
General information security news, for awareness.
.png)
Whitepapers
The World's Best SOC Teams Use Anvilogic

.png)




.png)